
About this episode
Get every episode summarized
Each time Data Breach Today Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
110 searchable segments. Every word is indexed and playable.
Full transcript
Data Breach Today Podcast — 'Systemic Risk' Stalks Healthcare Sector. Machine-transcribed; use the interactive transcript above to jump the player to any line.
I'm Mary Ann Kolbasek McGee, Executive Editor at Information Security Media Group. I'm here at HIMS26, speaking with Eric Decker, who is Vice President and CISO of Intermountain Health. Hi, Eric. Hi, Mary Ann. So Eric, you're here at HIMS speaking about systemic risk in the healthcare ecosystem. When it comes to different types of vendors and third parties, what are the top worries right now from a cybersecurity perspective for healthcare and why and what's changing? Yeah, so I think, I mean, everybody's aware of what happened with change healthcare. That is systemic risk materialized, so it was a risk that we've always had, but we didn't necessarily have the proper lens to find it. So not every vendor that's out there is actually going to be as critical into the pipeline of the healthcare ecosystem, and I think what we need to be doing and what we just announced today with the smart maps is how to identify critical functions that are specific to your organizations
and specific for the carrying of patients. So think like a critical function could be laboratory results, it could be a pharmaceutical drug, delivery, imaging, both diagnostic and therapeutic imaging, those are two different critical functions. These are all things that are absolutely critical for doing things like carrying for patients that present at the ED or in trauma. And when you map all of this out and then you start to understand where certain vendors have market convergence, say more than 30-40% of the market, now you have a material supplier to your organization that's also a choke point inside the whole ecosystem of healthcare, that's a potential hot point that we should be planning around. And had we done this prior to change healthcare, ideally what we would have seen is that the continuity to the path to resiliency of this where we're all eager to achieve is the ability to anticipate those types of hot points going down, knowing it's going to go down and building pathways
very quickly around it to bring your sustainability back up. So it's a refocusing of the problem, that's what systemic risk means in my mind's eye, and we are a massively connected ecosystem, and so you got to figure out where all those connection points connected to those material choke points. So in terms of the, you mentioned the SMART tool, the health sector, coordinating council, cybersecurity working group last October released the sector of mapping and risk management toolkit or SMART, which is much easier to say, and it provides actionable guidance for managing systemic risk and critical interdependencies throughout the health system. If there was one or two of the most important steps or pieces of advice that SMART provides, that you think are things that are commonly overlooked, but yet so important, if they don't do it, what would that be? And especially if you're under a resource healthcare system, and this is
so many people that can work on this, what would you recommend them focusing on? I mean, the first step in all of this is I would take the 12 critical functions that have been identified as SMART, go to your leadership and say which of these 12 critical functions are absolutely necessary for us to be up within a predetermined time frame, say five days. Can we live without this for more than five days or three days or whatever your metric is? You'll get an answer from your business as to, you know, either it's, yeah, we're okay or no, this doesn't apply to us or, you know, like that gasp of, like what do you mean five days? Like that's the way too long, you know, that's your clue to say now I need to dive deeper, and you'll be able to like rank order those 12, say take imaging as an example, and imaging inside an emergency department inside a trauma department is very important. And so that will help you guide towards like what the next step is, what's a, what's a level deeper? From there you can actually map out the clinical workflows for that one particular critical function, and then you'll be able to see
how it actually flows through within your ecosystem, and then also to your third party suppliers. That will then guide you into the next step, and so it will actually help you get going, like just take the first step, like ask the first questions, one of the 12, like what, how does it work? And you'll get off to the races. So now, in terms of systemic risk, how does AI kind of fit into that now? Is it a risk? Is it something you can help with risk? Where do you see that kind of fitting in? So AI, okay, so you have to think about AI and a few different types of capacities. You could have AI that is delivering a critical function. And if that is the case, then you just have to think of AI in the same bucket as any other technology. So if you've got AI delivering reads on imaging systems, okay, great, like where is that at? Is it connected inside the platform? Is it outside the platform? Are you digital workers connected to it? Like whatever that is, just keep the same business impact analysis flowing through that piece so that you understand
if the agent is there, that digital agent is doing the reads, and it's doing it autonomously, which I don't think anybody's doing yet, but if we can get there and producing results, then now you know that that's part of your systemic risk model. Your governance should help a crown for that and so forth. AI, like from a cyber angle, like introduces all kinds of new things, like there's new attack planes coming. We probably need a whole podcast just on that alone, but yeah, I would say like as you're doing your dependency mapping through your critical functions, you'll see that. And then hopefully with the critical function identified, and then now you say, like say there's an AI autonomous agent in there, hopefully you're going to be asking yourself the question, what's the accuracy associated this? How transparent is it? Is it clinically effective? Is it, that's all part of your AI governance that you should be doing? And you'll have a different lens attributed to it because now you're saying, okay, now we've got AI in the midst of a critical function. So it's extra levels of importance associated to that. So it just helps you with your
risk posture and understanding how to manage it. Do you see AI tools helping with the whole management of the systemic risk itself? I mean, there are actually, there are vendors that are out there that have all kinds of interesting data. So there are vendors, third party risk management vendors that actually collect data from third parties like doing the risk analysis that are actually mapping the, they've taken the smart map since it does this. They've taken the smart map and they put it inside their ecosystem and said, well, maybe I could actually see where how the maps actually lay themselves out for the whole, for their population and then how that airplanes with a customer and a client. So yeah, it absolutely has applicability. As with everything, it's dependent on the data source and do you have rich and accurate data for the AI agent to be able to like map all of that stuff out. But for sure, it can, it can be done. And the other promising technologies to help with this whole systemic risk management issue. Technology, I mean, honestly, I feel like most
of this is is not a technology solve. It is a process solve and a reframing of your risk, your risk mental model. We, we like to think that we have to cover the entire world and understand the entire world in order to like, whittle it down to like the most microcosmic issue that that will come into play. Unfortunately, when you do that and you take the, the, the realm of I'm going to drink all, I'm going to drink the ocean, you know, you drown. Like, it's just as simple as that. You can't do it. You got to sip. So the maps help you figure out how to take that proper sip of a drink of water inside the ocean of, of what ifs. And, and that, frankly, is the process side of the equation. And then, like I said before, I mean, there are, there are some vendors that have produced interesting tools to help you kind of think about it from a different way. But you, you at the end of the day, you must understand your process within your organization first and foremost. No
tools can be able to do that for you. And finally, you know, aside from the systemic risk issue, any promising technologies you're watching right now for security, cyber security that will, you know, help, help your organization. Yeah, I mean, just in the whole technology front in general, I mean, it, like, and back to the AI side of the house. I mean, there's between autonomous AI, you know, a, a, a, a, a, a, a, a, a, a, and the way you go about building that. And then personal assistant AI. So, Cloudbot and, um, Googles, like, um, their new, um, zero gravity or anti-gravity is what it's called. You know, all these, these, these tools that you can just install on your, on your device and it'll just start doing stuff. The, the thing that's challenging right now, and I think, and I think that, I think that we're all interested in seeing is like, how do we get to better observability around the entire ecosystem of what the agentic space is doing? What are those agents actually doing? You know, and making sure that you can understand that. Um, and is it, are they operating within the guardrail, such as setting up
and the policies that you're setting up and such organization? That is like runtime level decision making that needs to happen. This is beyond AI governance in general, sort of the process behind it. Um, there's a lot of interesting vendors here at him that are talking about this. I've been, I've been chatting with a lot of them just trying, trying to get their take. And, uh, frankly, I think that's like a necessary need as you're looking into how are you going to enable an agentic workforce, uh, in the coming years? Well, thank you, Eric. I've been speaking to Eric Decker. I'm Mary Ann Kolbosek-Miki, of Information Security Media Group. Thanks for joining us.
More episodes
More from Data Breach Today Podcast

Why 'Emerging Threats' Are Harder to Prioritize in the AI Era
Data Breach Today Podcast

The End of Static Security: Why AI Demands Real-Time Microsegmentation
Data Breach Today Podcast

Why Data Security Standards in Cancer Innovation Matter
Data Breach Today Podcast

How Main Line Health Secures Devices With Microsegmentation
Data Breach Today Podcast